feat: harden self-managed reconciliation
This commit is contained in:
@@ -94,7 +94,9 @@ describe("kuber config", () => {
|
||||
{ services: { app: { build: "." } } },
|
||||
process.cwd(),
|
||||
{},
|
||||
{ app: `registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}` },
|
||||
{
|
||||
app: `registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}`,
|
||||
},
|
||||
);
|
||||
const deployment = resources.find(
|
||||
(resource) => resource.kind === "Deployment",
|
||||
@@ -103,6 +105,39 @@ describe("kuber config", () => {
|
||||
`registry.example.com/team/kuber/project-app:latest@sha256:${"a".repeat(64)}`,
|
||||
);
|
||||
});
|
||||
|
||||
test("scopes the server RBAC self-management rules", async () => {
|
||||
const config = await loadConfig(process.cwd());
|
||||
const resources: any[] = [];
|
||||
await config.postRender?.(resources, {
|
||||
cwd: process.cwd(),
|
||||
project: "kuber-system",
|
||||
composeFile: "compose.yml",
|
||||
});
|
||||
|
||||
const role = resources.find((resource) => resource.kind === "Role");
|
||||
const manager = resources.find(
|
||||
(resource) => resource.kind === "ClusterRole",
|
||||
);
|
||||
expect(role.rules).toContainEqual({
|
||||
apiGroups: [""],
|
||||
resources: ["serviceaccounts"],
|
||||
resourceNames: ["kuber-server"],
|
||||
verbs: ["get", "update", "patch"],
|
||||
});
|
||||
expect(role.rules).toContainEqual({
|
||||
apiGroups: ["rbac.authorization.k8s.io"],
|
||||
resources: ["roles", "rolebindings"],
|
||||
resourceNames: ["kuber-server-auth"],
|
||||
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"],
|
||||
});
|
||||
expect(manager.rules).toContainEqual({
|
||||
apiGroups: ["rbac.authorization.k8s.io"],
|
||||
resources: ["clusterroles", "clusterrolebindings"],
|
||||
resourceNames: ["kuber-server-manager"],
|
||||
verbs: ["get", "update", "patch"],
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
describe("global config argument", () => {
|
||||
|
||||
Reference in New Issue
Block a user